Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
Link
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
Referrer-Policy
X-Varnish
X-Request-Id
X-Timer
CF-Cache-Status
X-AspNet-Version
Access-Control-Allow-Headers
X-Xss-Protection
Access-Control-Allow-Methods
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Check
X-Generator
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
Status
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Permitted-Cross-Domain-Policies
X-FRAME-OPTIONS
Content-Encoding
X-Iinfo
X-Content-Security-Policy
X-CDN
X-Buckets
X-Turbo-Charged-By
X-Request-ID
Upgrade
X-Type
WPE-Backend
Keep-Alive
X-Pass-Why
CF-Ray
X-Cache-Group
X-AH-Environment
Xkey
P3p
X-Backend
Access-Control-Max-Age
X-Age
Access-Control-Expose-Headers
X-Via
X-Drupal-Dynamic-Cache
EagleId
X-Pingback
X-Nginx-Cache-Status
X-Amz-Id-2
X-Amz-Request-Id
X-Kinja-Server-Push
X-Server-Powered-By
X-Server
X-Hacker
Grace
X-UA-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Varnish-Cache
X-Robots-Tag
Ali-Swift-Global-Savetime
Cf-Railgun
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-Page-Speed
X-Ua-Compatible
X-LiteSpeed-Cache
Request-Context
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Ac
Content-Location
X-Cache-Lookup
X-Amz-Version-Id
X-WebKit-CSP
X-Response-Time
X-Host
Surrogate-Control
X-OneAgent-JS-Injection
X-Rq
X-Cnection
X-Node
Server-Timing
X-Backend-Server
X-Readtime
Report-To
X-Rack-Cache
X-Server-Id
Request-Id
EagleEye-TraceId
X-Application-Context
Feature-Policy
X-Cloud-Trace-Context
X-ORACLE-DMS-ECID
X-Instart-Request-ID
X-CST
X-Iejgwucgyu
Edge-Control
X-EdgeConnect-Origin-MEX-Latency
X-Clacks-Overhead
X-EdgeConnect-MidMile-RTT
NEL
Rating
X-Country
X-Server-Name
X-TTL
X-DynaTrace
X-Varnish-TTL
X-MS-InvokeApp
X-Url
X-DataDome
Allow
X-Px
X-Country-Code
X-Origin-Cache
Pinterest-Generated-By
X-Vhost
X-Vname
X-TtlSet
X-PC
X-Cached
X-FTR-Request-ID
X-Ruxit-JS-Agent
X-Server-ID
RTSS
X-ESI
SPRequestGuid
X-Trace
X-Goog-Hash
X-VARITI-CCR
Charset
X-SharePointHealthScore
X-Powered-By-Plesk
X-GitHub-Request-Id
X-DynaTrace-JS-Agent
X-T
Accept-CH
X-Dispatcher
X-Powered-CMS
X-B3-TraceId
Public-Key-Pins
X-D2id
X-Mod-Pagespeed
PB-RID
PB-PID
Arc-Version
X-Mobile-Rewrite
X-F-Cache
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-Kinja-Server
Verso
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja
X-Kinja-Build
Content-MD5
X-ORACLE-DMS-RID
SPRequestDuration
SPIisLatency
X-Version
X-Shield-Request-Id
MS-Author-Via
X-Recruiting
X-Dns-Prefetch-Control
X-Abt-Application-Version
Nginx-Cache
X-Forwarded-Proto
X-TEC-API-VERSION
X-TEC-API-ORIGIN
Accept-CH-Lifetime
X-TEC-API-ROOT
X-Client-IP
X-HW
X-Oracle-Dms-Rid
X-DIS-Request-ID
X-N
X-Navigation-Version
X-Pinterest-Rid
Pinterest-Version
X-Upstream-Env
AR-ATIME
AR-CACHE
AR-PoweredBy
X-B
X-Amz-Rid
DynaTrace
X-Fastly-Request-ID
X-Origin-Upstream-Status
X-Upstream
X-Ser
X-Dw-Request-Base-Id
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Amz-Meta-S3cmd-Attrs
X-Hits
Fastly-Restarts
TCN
Realpath
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-XRDS-Location
X-Wix-Server-Artifact-Id
X-Accel-Buffering
Paypal-Debug-Id
X-Content-Options
Arr-Disable-Session-Affinity
Service-Worker-Allowed
X-NF-Request-ID
X-Acc-Meta-Resource-Type
X-Pad
X-Goog-Storage-Class
S
Tracecode
Access-Control-Request-Method
X-Use-Magma
X-Litespeed-Cache
X-Content-Digest
X-Id
X-Debug
X-Varnish-Age
Edge-Cache-Tag
X-Vcap-Request-Id
X-Oneagent-Js-Injection
Front-End-Https
X-MSEdge-Ref
X-Mrf-Section-Lastmod
Mrf-Cache-Status
MRF-Tech
X-Mrf-Item-Lastmod
X-ATG-Version
X-Frontend
X-IPLB-Instance
X-FTR-Backend
X-PressLabs-Stats
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Realm
X-FTR-DC
X-FTR-Expires
X-RateLimit-Remaining
X-Kinsta-Cache
MicrosoftSharePointTeamServices
X-Logged-In
X-B3-TraceId-Primal
X-HS-Hub-Id
X-HS-Content-Id
Rt-Fastcgi-Cache
Surrogate-Key
X-Request-Received
X-Forwarded-For
X-Request-Processing-Time
X-Cache-Hit
X-Amz-Cf-Pop
Fastcgi-Cache
X-Sol
X-Middleton-Display
Display
X-Zen-Fury
X-Edge-Location
AMP-Access-Control-Allow-Source-Origin
Backend-Timing
X-Analytics
X-Rid
X-Debug-Info
Powered-By-ChinaCache
X-Amzn-Trace-Id
X-HS-Cache-Config
Host
X-Revision
X-User-Agent
Server-Name
X-FastCGI-Cache
X-FTR-Cache-Host
TP-Cache
TP-L2-Cache
FilterID
X-Fastcgi-Cache
X-Akam-SW-Version
Ar-Sid
X-CF-Powered-By
AR-Request-ID
X-Middleton-Response
Response
X-TA-CDN-Provider
X-Drupal-Cache-Tags
X-Cache-Key
X-Magnolia-Registration
X-SS-Set-Cookie
X-Mobile
X-Newrelic-App-Data
X-SERVER
Refresh
X-NewRelic-App-Data
Cache-Status
X-B3-Sampled
X-Grace
X-VCache
X-Accel-Expires
X-Cached-By
X-GUploader-UploadID
Host-Header
X-NWS-LOG-UUID
X-AOL-HN
X-Varnish-Backend
ServerID
X-Webkit-CSP
X-Node-Name
X-Whom
Eomportal-Instance
X-Content-Security-Policy-Report-Only
X-Device-Type
X-Cache-2
X-Cluster
X-Tumblr-User
X-B-Cache
X-Tumblr-Pixel
X-FB-Debug
X-Via-JSL
X-Signature
X-Tumblr-Pixel-0
X-Instance
X-Platform-Server
X-Akamai-Edgescape
X-Webkit-Csp
X-Cache-Control
X-Drupal-Cache-Contexts
X-LB-Cache
X-Ruxit-Js-Agent
X-Varnish-Hostname
X-Page-Id
X-Framework
X-Generated-By
X-BCube-Filmed-By
X-Handled-By
Cleartype
X-App-Environment
X-Request-Guid
X-Srv
X-URL
X-Cache-Rule
X-Cache-Action
X-App-Server
X-Activity-Id
X-AppVersion
Cache-Tag
X-Az
Alternate-Protocol
DC
X-Ttl
Source
Liferay-Portal
X-Content-Powered-By
X-Cache-Server
X-Hostname
Retry-After
X-HS-Combine-CSS
X-Varnish-Grace
X-WPE-Loopback-Upstream-Addr
X-WA-Info
X-App-Version
MS-CV
X-Daa-Tunnel
X-Geo-Country
X-Varnish-Server
HostName
X-Correlation-Id
X-Esi
X-Amz-Replication-Status
Public-Key-Pins-Report-Only
Server-Node
X-TT
X-Wix-Request-Id
X-Seen-By
AR-SID
ViewerVersion
Webserver
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
X-WebKit-CSP-Report-Only
X-Cache-NE
AsisCache
X-Response-Served-From
Pagespeed
Actual-Object-TTL
X-Amz-Apigw-Id
Upgrade-Insecure-Requests
Accept-Charset
X-Amzn-RequestId
SRV
X-GeoIP
GEO-INFO
X-RequestSource
X-Locale
X-Jobs
ServedBy
X-Varnish-Hits
Viewport
X-Edge-Cache-Key
X-Contextid
X-Yottaa-Metrics
Payment
X-S
X-Servedby
X-Yottaa-Optimizations
X-Edge-Cache
X-FW-Server
X-FW-Serve
X-FW-Hash
X-FW-Type
X-UUID
X-FW-Static
X-Status
X-TX-ID
X-Varnish-IP
X-Adobe-Content
X-Cacheable-TTL
X-XRDS-LOCATION
X-Adobe-Loc
X-TT-TIMESTAMP
S-Cnection
X-Origin-Server
X-Vg-Webcache
X-Cache-TTL-Remaining
X-Hyper-Cache
X-Correlation-ID
Cache
X-Cache-Age
X-Cache-Operation
X-Amz-Server-Side-Encryption
Server-Info
X-Forwarded-Host
X-Real-IP
Datacenter
X-GRACE
X-RateLimit-Limit
Served-By
X-Geo-Segment
X-Region
X-Akamai-Request-ID2
Access-Control-Allow-Method
X-Mode
X-DataStream-Cache-Status
X-CLOUD-TRACE-CONTEXT
Healthy
X-Content-Type
X-Sucuri-ID
CACHE
X-Ezoic-Cdn
X-Akamai-Transformed
X-Rendered-As
X-Path-Route
X-Zipkin-Id
X-Rule
X-Upgrade-Enabled
Fastcgi-Useragent
Fastcgi-X-Cache
X-Site-Version
X-Generated
X-Is-Bot
X-JoinUs
X-L-Path
X-Environment-Context
X-Detected-As
Meta-Geo
Machine
X-Cache-Config
X-Cache-Var
X-Cache-Var-Map
Fastcgi-X-Cache-Version
X-Ocache
X-Proxied
X-RN-RSRV
X-Routing-Service
X-Proxy
X-Agile
Now
X-Access
L5d-Success-Class
X-Viewer-Country
X-Request-Time
X-TNCMS
X-Agile-Age
X-Amz-Meta-Surrogate-Control
X-Human
Country
X-Loop
X-Section
X-Format
X-NGENIX-Cache
X-Birta-Cache-Post
X-Birta-Served
X-CDN-Cache
X-Agile-Id
X-Hosted-By
From-Origin
S-Rt
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Property-Id
X-Tb
Origin-Edge-Control
X-OCL
Cache-Name
DB-Nickname
X-Geo
X-Pc-Hit
TWC-Locale-Group
TWC-Privacy
X-Grey
X-Pc-Appver
X-Hit
X-Labrador-Cache-Channel
X-ServerID
X-CCM
X-Cache-Category-Id
Webcakes-App-Version
Webcakes-App-Name
Webcakes-Region
X-Pc-Key
Xserver
X-FC-Vary-Parameters
OT-Force-Account-Verify
X-Via-Fastly
Origin-Cache-Control
X-PCL
X-Origin-Hint
X-Upstream-CT
Accept-Language
X-VG-TLSProxy
X-IP
X-Web-Node
X-Cdn
HitInfo
X-EIG-Tracking-Id
X-Upstream-HT
X-Pubstack
HitType
X-OVcl-Cache
X-ProcessESI
X-BYPASS-REASON
X-OVcl
X-ProxyCache-Status
X-Xfnlog-Site
X-Original-Request
NGB
X-ProxyCache-Key
X-Origin
X-RemovedCookies
X-Proxy-Build
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-Sorting-Hat-ShopId
X-Www-Served-By
X-Via-CDN
Selected-FE
Azure-Version
X-ShardId
X-ShopId
Azure-SlotName
Azure-SiteName
Azure-InstanceId
Azure-RegionName
LB
X-Microcachable
X-Shopify-Stage
X-Timing-Wait
Mn-Server-Ip
X-Cluster-Node
Filters
X-App-Name
X-UA-Device-Type
X-TWH-CORRELATION-ID
X-Cache-Remote
X-Twitter-Response-Tags
X-Transaction
X-Rocket-Nginx-Bypass
X-RTag
X-Connection-Hash
Ms-Operation-Id
X-Internal-Host
X-NCache
X-Cache-Enabled
X-UA
X-Tumblr-Pixel-3
Time
IBM-Web2-Location
X-CACHE-KEY
X-Pc-Date
X-Cache-TTL
X-Pc-Host
Access-Control-Request-Headers
X-Guploader-Uploadid
X-PHP-Backend
X-Unique-ID
X-LJ-Flow-ID
X-VWS-Id
X-TIME
X-Origin-CC
X-Proto
X-NodeID
X-SplitTest
X-Nginx-Cache
X-AWS-Id
Cache-Hits
Content-Script-Type
Content-Style-Type
We-Hiring
X-Cdn-Forward
Mail-Subject
X-Vgn-Hpd-Reason
X-Storage
NtCoent-Length
X-Time-Microsecs
X-Port
X-MP-GENERATED-AT
X-Real-Ip
X-Source
X-Edge-IP
Backend
X-Webstats-RespID
X-Akamai-Request-ID
X-Backend-Name
Cache-Tags
X-APP-VERSION
X-Ms-Lease-Status
X-Ms-Version
X-Ms-Blob-Type
X-Debug-Cache
X-Ms-Request-Id
X-Varnish-Cacheable
X-Distil-CS
X-Csrf-Token
X-Endurance-Cache-Level
X-CACHE-GROUP
Locale
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Origin-Response-Time
X-Ua
X-Redis-Cache
PageSpeed
X-Ratelimit-Limit
X-Varnish-Beresp-Status
Warning
X-Varnish-Beresp-Grace
X-Croise-Owner
User-Agent
X-EdgeConnect-Cache-Status
X-B3-Spanid
X-Nc
X-NWS-UUID-VERIFY
X-CACHE-AGE
X-A-Dam
X-A-Ccd
X-A-Dcw
X-A-Dgt
X-A-Wwc
Xc-Version
X-A
VivaBuild
TSSecure
Server-Host
UCS
V-Age
Viewtype
X-We-Are-Hiring
X-Accel-Expires-Debug
X-Store
X-Trv-Group
X-B-Cookie
X-SRCache-Key
X-Sn-Servicetimems
X-UE-Client-Country
X-VG-WebServer
X-Via-SSL
X-Aed
X-Amz-Meta-Cache-Control
X-Via-Edge
X-Application
Rt-Proxy-Cache
Resin-Trace
HA-Geocity
Content-Disposition
HA-Geocountry
Cache-Prefix
HA-Geolon
HA-Geolat
Country-Code
HA-Cloudapp
Ec-Rule-Version
Fastly-SWR
Fly-Cache
Fly-Request-Id
GMS-Ver
HA-Georegion
BehaviorPad-Version
Meta-Geo-Continent
Ajk
Mobile-Detection-Method
Powered-By
Rendered-Blocks
MD5-Digest
HA-Urlpath
Arc-Country
Ha-Gx-Prefs
HA-Host
HA-Ipaddr
HA-Servedtime
X-BB-ID
X-Server-Time
X-G
X-Generated-In
X-From
X-Fetched-On
X-External-Request-Id
X-F5-Cache
X-GeoIP-Country-Code
X-Varnish-Cache-Hits
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Storage-Class
X-Hash
X-Varnish-Beresp-Ttl
X-Eu-Site
X-ElasticPress-Search
X-Debug-Cookies
X-Debug-Log
X-Date
X-D
X-PERF
X-Destination
X-Developer
X-ApacheServer
X-CF-Lambda-Version
X-DPWN-IS-SECURE
X-C
X-Died
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-CDN-Forward
X-Cache-Bucket
X-Cache-Host
X-Region-Sid
X-Cache-Backend
Fastly-SIE
X-Rewrite-Enabled
X-ScT
X-Server-By
X-S-Cookie
X-Rojux
X-BBXSRF
X-Cache-URL
X-Rebelmouse-Surrogate-Control
X-Irp-Debug
X-Logtrace-Id
X-IN-WAF
X-IN-SSL-APIGATEWAY
X-IN-APIGATEWAY
X-NU-AKA-ACS-Version
X-NX-Host
X-Cdn-Origin
X-Rebelmouse-Cache-Control
X-PAYTM-SRV-ID
X-CF-Lambda-Fn
X-Org
X-CGP
Fastly-SSL
X-Dc
X-Mshield-Cache-Status
Version
X-Mrs-Age
Cache-Key
X-Mrs-Cache-Hits
X-Mrs-Cache
Pagetype
X-Developers
X-Dispatcher-Server
X-Flog
X-Hl-Ver
X-Info
X-Hello
X-GeoIP-City
X-FW-Version
X-Epic-Correlation-Id
X-Clientip
Www
X-ABtesting
Uber-Trace-Id
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Auto-Login
X-Backend-Host
X-Cache-Id
X-Key
X-Cache-FS-Status
X-Backend-Url
X-Backend-State
X-Core-Value
X-Location
X-Trace-Id
X-UnsetCookies
X-Thinkindot-L3
X-Dynatrace-Js-Agent
X-ServiceProvider
X-SIPLIST1
X-User
X-V
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-VServer
X-Via-NSCOPI
X-Var-Ttl
X-Variation
X-S-Maxage
X-Response-By
Fastly-Soc-X-Request-Id
X-Platform
X-No-Session
X-MServer
Thinkindot-CacheControl
X-Matched-Rule
X-Qloud-Router
X-Time
X-Request-Start
X-Request-URI
X-Release
X-Reboot
X-Parent-Response-Time
X-Layer
X-DC
Frame-Options
Platform
FSS-Cache
FSS-Proxy
WZWS-RAY
Decoy-Debug-Status
User-Cache-Control
Is-Eu
RNT-Time
RNT-Machine
Decoy-Debug-Key
Heartbleed
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Backend-Name
Release
Apple-News-Services-Host
Pramga
GW-Server
Countrycode
Apple-News-Services-Handled
X-Powered-By-ANYU
Decoy-Debug-TTL
SN
AKAMAI
Memcached
Server-ID
Section-Io-Cache
Origin
IsBot
Adler-Geo
X-Datadome
X-NC
X-Newrelic-Synthetics
X-Instance-Name
X-Hnp-Log
Cache-Cookie-Set-From
MI-Cache-Age
X-Li-Fabric
MI-Cache
X-LI-Proto
X-Nginx-Cache-Key
Magicmarker
Kp-EeAlive
X-MI-In-Market
X-Policy
X-RCS-CacheZone
X-P-T
X-LI-UUID
X-Li-Pop
X-Thanos
X-Passed-To-DLL
X-Passed-To-PostProcessResponse
X-Returned-From
X-Passed-To-BeforeDispatch
X-Passed-To
X-Actual-URL
X-Node-Id
X-Returned-From-BeforeDispatch
X-Returned-From-DLL
Group
V-Cache
X-Request-UUID
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Returned-From-PostProcessResponse
X-Stale
On-Server
Fastly-Backend-Name
Cache-Cookie-Set-Lfrom
X-Sf
X-Swa-Ws
X-Server-IP
X-Served-From
X-Secret
X-Sentry-ID
X-Goog-Meta-Goog-Reserved-File-Mtime
X-TT-LOGID
Esi-Enabled
X-Worker
X-WebServer
X-VCT
X-Up
X-Varnish-Action
Cache-Cookie-Set-Idcheck
X-Phone
X-Unique-Id-Primal
X-Sucuri-Cache
Server-Int
X-Device-Os
Request-EU
Request-Country
Odigeo-Trace-Id
X-Core-Mission
Pragrma
Web-Mar-Node
X-CUA
X-Crawler
X-Distributor
True-Client-Country-4JS
X-Fastly-Cache
X-Gen-Mode
X-Bip
X-Gannett-Site-Version
X-Block-Status
X-Cache-Debug
X-Cache-Expires
X-MSEdge-Features
Who
REQUESTUUID
X-NODE
X-HOST
Proxy-Connection
X-MSEdge-Flight
CDCHOST
X-Cache-CFC
X-Refresh
X-Fstrz
MI-API
X-Owner
X-Page-Type
X-Servername
MIME-Version
RequestId
Fusion-Source
Cteonnt-Length
HTTPS
Fusion-Component-Id
X-Req
Fusion-Content-Source
Fusion-Content-Id
X-Be
Fusion-Template-Id
X-Pjax-Url
X-Kong-Upstream-Latency
X-SN
X-Kong-Proxy-Latency
X-Backend-TTL
X-Oracle-Dms-Ecid
X-Cache-Srv
X-Edge-Server
X-Ms-Lease-State
Memory
X-Origin-TTL
Cdn-Host
NodeID
X-GZip
Cdn-Request-Time
Cdn
X-Server-Group
ProcessTime
SD-X-WS
Amp-Access-Control-Allow-Source-Origin
X-Servedbyhost
X-Content-Age
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Wa
SS
CF-IPCountry
Mime-Version
X-Protected-By
X-COUNTRY
A
X-Aicache-OS
X-Origin-Host
X-ND-Cache
GeoIP-Country-Code
X-Origin-Expires
X-Ckpd-Fst-Backend
X-BB-IP
X-Origin-Date
CDN
GeoIP-Latitude
X-SRV
X-Varnish-Beresp-TTL
Is-Session-Tracking
X-StackifyID
Get-Access-Time
XServer
X-APP
X-Pf-Uncompressing
X-B3-Traceid
X-Fastly-Country-Code
PageType
Processtime
X-PHP-Host
Geoip-Latitude
Node
GeoIp-Country-Code
Serverid
X-Unique-Id
Vix-Hermes-Req-Id
Cache-Tv-Group
X-Requestid
X-Proxy-Upstream
X-Cache-Info
PICS-Label
X-Proxy-Cache-Status
X-Varnish-Url
X-Ratelimit-Remaining
X-CSRF-Token
X-Gdpr
X-WA
X-Load-Cache
X-Nananana
Nel
X-Fastly-Cache-Hits
X-RateLimit-Limit-Second
X-Generation-Time
Cf-Ipcountry
X-BACKEND-TTL
X-ID
X-RateLimit-Remaining-Second
X-UPSTREAM-Address
Cache-Provider
X-SERVER-NAME
X-Planisys-CDN-TTL
X-ServedByHost
X-RequestId
X-Planisys-CDN-Cache
X-FireWall-Port
DataCenter
X-Planisys-CDN-Rules
URI
WP-Super-Cache
X-HS-Status
X-Check-Cacheable
Request-Time
X-GZIP
Hostname
X-FORWARDED-FOR
Host-ID
PFcat
X-EC-Security-Audit
X-Fastly-Backend-Reqs
X-Micro-Cache
X-CS
X-Front
X-NGINX-Cache
X-Server-W
X-B3-SpanId
X-Debug-Cache-Fetch
X-GDPR
X-WR-MODIFICATION
X-Debug-Cache-Store
X-Debug-Cache-Expiry
X-FB-TRIP-ID
NGX
X-VG-WebCache
X-VarnPar1
X-VarnCache
X-Fe
X-DataStream-Origin-MEX-Latency
X-Surge-Debug
X-Svr
X-DataStream-MidMile-RTT
X-BE
X-PARISIEN-Cache-Rendered
T-Server
X-HTML-Edge-Cache
X-GEO
X-Swift-Error
X-Atg-Version
Ohc-File-Size
X-Generated-On
X-HTML-Minification-Powered-By
Ohc-Response-Time
ServerName
Lfy
Https
Pics-Label
X-Cdn-Srv
X-IPS-LoggedIn
X-PJAX-URL
X-Level-Front-Cache
X-Instart-Info
RequestUuid
Requestid
X-Akamai-SSL-Client-Sid
X-Amz-Meta-S3b-Last-Modified
X-ServerName
N-Cache
X-VarnPar2
WebServer
X-RAMCache
X-Cache-Ttl
X-PF-Uncompressing
X-Distil-Cs
X-PAGE-TYPE
X-From-Cache
X-M-Reqid
X-Qnm-Cache
X-M-Log
Build-Number
X-Serial
NnCoection
X-Akamai-ERPolicy
Cdn-Src-Port
X-Akamai-ERRuleID
X-Gen-Id
X-Alicdn-Da-Ups-Status
X-SB
X-VC
SID
X-Dw-Trace-Id